1. Controller
The controller is Eyelo SA, Rue du Simplon 37, 1006 Lausanne, Switzerland, UID CHE-108.174.302. Requests may be sent to support@llmhub.ch.
2. Data processed
- Account data: optional name, email address, status and verification information.
- Security data: sessions, IP addresses, access dates and authentication events.
- Commercial data: top-ups, Stripe references, amounts, currency, bonuses, refunds and disputes.
- Usage data: relevant keys, models, token volumes, costs, latency, status and credit entries.
- Data voluntarily provided to support.
3. Prompts and responses
LLMHub does not log or permanently archive prompt and response content. A very short-lived technical cache may be used where strictly required to operate the service.
Requests are sent to RouterLab. Further processing depends on the selected route and, where applicable, the corresponding provider.
4. Purposes and legal bases
- Perform the agreement: create accounts, provide the API, manage credits and process orders.
- Protect the service: authentication, abuse prevention, security and diagnosis.
- Comply with legal, tax, accounting and regulatory duties.
- Respond to support and improve technical operation based on Eyelo SA's legitimate interests.
- Obtain consent where required.
5. Providers and hosting
Stripe processes payments and fraud prevention. RouterLab runs and routes model requests. Emails are sent through Eyelo SA's internal services.
Infrastructure directly controlled by Eyelo SA is located in Switzerland and Germany.
6. Cookies
LLMHub uses only cookies required for sign-in, security, language selection and payments. No advertising cookies or audience analytics tools are used.
7. Disclosure and transfers
Data is not sold or rented. It may be disclosed to Stripe, RouterLab, the provider associated with the selected route, a competent authority or a party essential to security.
Some routes may involve processing outside Switzerland or the European Economic Area. Safeguards, locations and periods then depend on the relevant route and provider.
8. Retention periods
Account data is retained during the contractual relationship, then deleted or anonymised when no longer required, subject to legal duties and disputes.
Accounting data and transaction evidence may be retained for up to ten years where required by Swiss law. Security logs are retained for a period proportionate to abuse prevention and diagnosis.
Data processed by Stripe, RouterLab or a provider is also subject to the periods applying to those services.
9. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction of or objection to certain processing, and information about how data is processed.
Where the GDPR applies, you may also request portability, withdraw consent and lodge a complaint with the competent authority. Identity verification may be required.
10. Security and updates
Eyelo SA applies proportionate measures including access control, encrypted communications, data minimisation and security logging. No connected system can guarantee absolute security.
This policy may change with the service, providers or applicable law. The version and date are published here and material changes are communicated appropriately.